2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21197 | MEDIUM | 4.9 | 0.9% | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t... |
| CVE-2024-21196 | MEDIUM | 6.5 | 0.9% | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are af... |
| CVE-2024-21195 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions ... |
| CVE-2024-21194 | MEDIUM | 4.9 | 0.9% | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2024-21193 | MEDIUM | 4.9 | 0.9% | Oct 15, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected... |
| CVE-2024-21192 | MEDIUM | 4.4 | 0.2% | Oct 15, 2024 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: Web... |
| CVE-2024-21191 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component:... |
| CVE-2024-21190 | HIGH | 7.5 | 0.5% | Oct 15, 2024 | Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cl... |
| CVE-2024-21172 | CRITICAL | 9 | 0.5% | Oct 15, 2024 | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ... |
| CVE-2024-41344 | HIGH | 7.5 | 0.2% | Oct 15, 2024 | A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator passw... |
| CVE-2024-35584 | HIGH | 8.8 | 5.9% | Oct 15, 2024 | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL... |
| CVE-2024-5749 | HIGH | 7.5 | 1.2% | Oct 15, 2024 | Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials. |
| CVE-2024-48915 | HIGH | 8.7 | 0.4% | Oct 15, 2024 | Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, cer... |
| CVE-2024-9676 | MEDIUM | 6.5 | 1.3% | Oct 15, 2024 | A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage lib... |
| CVE-2024-9506 | LOW | 3.7 | 0.5% | Oct 15, 2024 | Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulner... |
| CVE-2024-48914 | CRITICAL | 9.1 | 59.8% | Oct 15, 2024 | Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as... |
| CVE-2024-48913 | MEDIUM | 5.9 | 0.3% | Oct 15, 2024 | Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by... |
| CVE-2024-48624 | MEDIUM | 5.3 | 0.2% | Oct 15, 2024 | In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a refl... |
| CVE-2024-48623 | MEDIUM | 5.3 | 0.2% | Oct 15, 2024 | In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited ... |
| CVE-2024-48622 | MEDIUM | 6.6 | 0.3% | Oct 15, 2024 | A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admi... |
| CVE-2024-47876 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea... |
| CVE-2024-47874 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treat... |
| CVE-2024-47824 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starti... |
| CVE-2024-47779 | HIGH | 7 | 0.4% | Oct 15, 2024 | Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a ... |
| CVE-2024-47771 | HIGH | 7 | 0.6% | Oct 15, 2024 | Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now